Case study — Secure Enclave · CMMC Level 2 certification

110 out of 110. Zero POA&Ms. One pass.

RPS Defense completed its CMMC Level 2 assessment with every requirement met and every assessment objective verified — no conditional status, no remediation clock. The environment behind the score: Essendis's turnkey Secure Enclave on Microsoft 365 GCC High, deployed with the security and compliance program to run it. Here's how the engagement ran.

See how they did it
Why a conditional pass wasn't an option

RPS Defense — Remotely Piloted Solutions, LLC — is a Dallas-based defense services company: manned and unmanned aircraft operations, aircrew and UAS training, intelligence support, and flight test for the Department of Defense and its primes. Its everyday work product — mission data, training curricula, technical data tied to DoD aviation programs — is exactly the Controlled Unclassified Information that CMMC Level 2 exists to protect. A conditional pass (88 or more requirements met, with a 180-day clock to close the rest) was technically available. RPS's leadership set the target at the top: everything met, first time. Rather than re-engineer its entire network, RPS deployed the Essendis Secure Enclave — a turnkey CMMC Level 2 boundary on Microsoft 365 GCC High — and scoped the assessment to it.

Client: RPS Defense — manned & unmanned aircraft services

Standard: NIST SP 800-171 R2 · 110 requirements · 320 objectives

Solution: turnkey Essendis Secure Enclave on Microsoft 365 GCC High

Assessor: accredited C3PAO · runway: roughly 7 months

Result: 110/110 — Final Level 2 status

Four phases, no surprises saved for assessment week

The plan was built backwards from a simple rule: nothing the C3PAO asks for should be created, found, or explained for the first time in front of an assessor.

01

Scope it — readiness & boundary

Mapped where CUI actually flowed, drew the enclave boundary around it, and scored the starting position against all 110 requirements — honestly, including the ugly parts.

02

Deploy it — enclave & program

Stood up the turnkey Secure Enclave on Microsoft 365 GCC High with the technical controls pre-configured, then laid down the security and compliance program around it — policies, procedures, and a System Security Plan that matched the environment as deployed. Every one of the 320 assessment objectives got an owner and an evidence artifact.

03

Prove it — pressure test

Before the C3PAO arrived, Essendis's advisory practice pressure-tested the program — walking the controls, pulling the evidence, and asking the hard questions first.

04

Pass it — assessment week

The C3PAO examined, interviewed, and tested. The RPS team fielded the questions, because by then the answers were theirs.

Every family. Every objective. Met.

A Level 2 assessment walks all fourteen NIST SP 800-171 control families, verifying each of the 320 assessment objectives behind the 110 requirements — all of it scoped to the Secure Enclave. Here's how RPS Defense scored.

110/110
Requirements met
320/320
Objectives verified
0
POA&M items
110
SPRS score

Access Control — 22/22 met

Awareness & Training — 3/3 met

Audit & Accountability — 9/9 met

Configuration Management — 9/9 met

Identification & Authentication — 11/11 met

Incident Response — 3/3 met

Maintenance — 6/6 met

Media Protection — 9/9 met

Personnel Security — 2/2 met

Physical Protection — 6/6 met

Risk Assessment — 3/3 met

Security Assessment — 4/4 met

System & Comms Protection — 16/16 met

System & Info Integrity — 7/7 met

"We expected to pass. We didn't expect the assessors to run out of questions — every artifact they asked for already existed, named and dated."

— RPS Defense, Program Manager

Why the score held up

01

A turnkey boundary

The Secure Enclave arrived on Microsoft 365 GCC High with the technical controls already configured and documented — remediation started from a hardened baseline, not a blank page.

02

Objective-level rigor

Every one of NIST SP 800-171's 110 controls was assessed against its own objectives, not just the control title.

03

An SSP that matched reality

The System Security Plan described the environment as built, not as originally scoped, so nothing needed explaining away.

04

Built for purpose

The enclave wasn't a general-purpose environment retrofitted to a standard. It was designed from day one as a CMMC Level 2 boundary for defense contractors — so every control mapped cleanly to how the environment actually runs.

Want a program that survives an audit, not just a review?

Book a discovery call

CMMC Program Guide

The phases, levels, and routes to certification this engagement followed.

See the guide

Secure Enclave

The turnkey CMMC Level 2 boundary this assessment ran on.

Explore the enclave

Dynamics 365

Business Central and Sales, running outside the compliance boundary.

See the platform